query_builder.ts 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413
  1. import * as queryDef from './query_def';
  2. import { ElasticsearchAggregation } from './types';
  3. export class ElasticQueryBuilder {
  4. timeField: string;
  5. esVersion: number;
  6. constructor(options: any) {
  7. this.timeField = options.timeField;
  8. this.esVersion = options.esVersion;
  9. }
  10. getRangeFilter() {
  11. const filter: any = {};
  12. filter[this.timeField] = {
  13. gte: '$timeFrom',
  14. lte: '$timeTo',
  15. format: 'epoch_millis',
  16. };
  17. return filter;
  18. }
  19. buildTermsAgg(aggDef: ElasticsearchAggregation, queryNode: { terms?: any; aggs?: any }, target: { metrics: any[] }) {
  20. let metricRef, metric, y;
  21. queryNode.terms = { field: aggDef.field };
  22. if (!aggDef.settings) {
  23. return queryNode;
  24. }
  25. queryNode.terms.size = parseInt(aggDef.settings.size, 10) === 0 ? 500 : parseInt(aggDef.settings.size, 10);
  26. if (aggDef.settings.orderBy !== void 0) {
  27. queryNode.terms.order = {};
  28. if (aggDef.settings.orderBy === '_term' && this.esVersion >= 60) {
  29. queryNode.terms.order['_key'] = aggDef.settings.order;
  30. } else {
  31. queryNode.terms.order[aggDef.settings.orderBy] = aggDef.settings.order;
  32. }
  33. // if metric ref, look it up and add it to this agg level
  34. metricRef = parseInt(aggDef.settings.orderBy, 10);
  35. if (!isNaN(metricRef)) {
  36. for (y = 0; y < target.metrics.length; y++) {
  37. metric = target.metrics[y];
  38. if (metric.id === aggDef.settings.orderBy) {
  39. queryNode.aggs = {};
  40. queryNode.aggs[metric.id] = {};
  41. queryNode.aggs[metric.id][metric.type] = { field: metric.field };
  42. break;
  43. }
  44. }
  45. }
  46. }
  47. if (aggDef.settings.min_doc_count !== void 0) {
  48. queryNode.terms.min_doc_count = parseInt(aggDef.settings.min_doc_count, 10);
  49. }
  50. if (aggDef.settings.missing) {
  51. queryNode.terms.missing = aggDef.settings.missing;
  52. }
  53. return queryNode;
  54. }
  55. getDateHistogramAgg(aggDef: ElasticsearchAggregation) {
  56. const esAgg: any = {};
  57. const settings = aggDef.settings || {};
  58. esAgg.interval = settings.interval;
  59. esAgg.field = this.timeField;
  60. esAgg.min_doc_count = settings.min_doc_count || 0;
  61. esAgg.extended_bounds = { min: '$timeFrom', max: '$timeTo' };
  62. esAgg.format = 'epoch_millis';
  63. if (settings.offset !== '') {
  64. esAgg.offset = settings.offset;
  65. }
  66. if (esAgg.interval === 'auto') {
  67. esAgg.interval = '$__interval';
  68. }
  69. if (settings.missing) {
  70. esAgg.missing = settings.missing;
  71. }
  72. return esAgg;
  73. }
  74. getHistogramAgg(aggDef: ElasticsearchAggregation) {
  75. const esAgg: any = {};
  76. const settings = aggDef.settings || {};
  77. esAgg.interval = settings.interval;
  78. esAgg.field = aggDef.field;
  79. esAgg.min_doc_count = settings.min_doc_count || 0;
  80. if (settings.missing) {
  81. esAgg.missing = settings.missing;
  82. }
  83. return esAgg;
  84. }
  85. getFiltersAgg(aggDef: ElasticsearchAggregation) {
  86. const filterObj: any = {};
  87. for (let i = 0; i < aggDef.settings.filters.length; i++) {
  88. const query = aggDef.settings.filters[i].query;
  89. let label = aggDef.settings.filters[i].label;
  90. label = label === '' || label === undefined ? query : label;
  91. filterObj[label] = {
  92. query_string: {
  93. query: query,
  94. analyze_wildcard: true,
  95. },
  96. };
  97. }
  98. return filterObj;
  99. }
  100. documentQuery(query: any, size: number) {
  101. query.size = size;
  102. query.sort = {};
  103. query.sort[this.timeField] = { order: 'desc', unmapped_type: 'boolean' };
  104. // fields field not supported on ES 5.x
  105. if (this.esVersion < 5) {
  106. query.fields = ['*', '_source'];
  107. }
  108. query.script_fields = {};
  109. if (this.esVersion < 5) {
  110. query.fielddata_fields = [this.timeField];
  111. } else {
  112. query.docvalue_fields = [this.timeField];
  113. }
  114. return query;
  115. }
  116. addAdhocFilters(query: any, adhocFilters: any) {
  117. if (!adhocFilters) {
  118. return;
  119. }
  120. let i, filter, condition: any, queryCondition: any;
  121. for (i = 0; i < adhocFilters.length; i++) {
  122. filter = adhocFilters[i];
  123. condition = {};
  124. condition[filter.key] = filter.value;
  125. queryCondition = {};
  126. queryCondition[filter.key] = { query: filter.value };
  127. switch (filter.operator) {
  128. case '=':
  129. if (!query.query.bool.must) {
  130. query.query.bool.must = [];
  131. }
  132. query.query.bool.must.push({ match_phrase: queryCondition });
  133. break;
  134. case '!=':
  135. if (!query.query.bool.must_not) {
  136. query.query.bool.must_not = [];
  137. }
  138. query.query.bool.must_not.push({ match_phrase: queryCondition });
  139. break;
  140. case '<':
  141. condition[filter.key] = { lt: filter.value };
  142. query.query.bool.filter.push({ range: condition });
  143. break;
  144. case '>':
  145. condition[filter.key] = { gt: filter.value };
  146. query.query.bool.filter.push({ range: condition });
  147. break;
  148. case '=~':
  149. query.query.bool.filter.push({ regexp: condition });
  150. break;
  151. case '!~':
  152. query.query.bool.filter.push({
  153. bool: { must_not: { regexp: condition } },
  154. });
  155. break;
  156. }
  157. }
  158. }
  159. build(target: any, adhocFilters?: any, queryString?: string) {
  160. // make sure query has defaults;
  161. target.metrics = target.metrics || [queryDef.defaultMetricAgg()];
  162. target.bucketAggs = target.bucketAggs || [queryDef.defaultBucketAgg()];
  163. target.timeField = this.timeField;
  164. let i, j, pv, nestedAggs, metric;
  165. const query = {
  166. size: 0,
  167. query: {
  168. bool: {
  169. filter: [
  170. { range: this.getRangeFilter() },
  171. {
  172. query_string: {
  173. analyze_wildcard: true,
  174. query: queryString,
  175. },
  176. },
  177. ],
  178. },
  179. },
  180. };
  181. this.addAdhocFilters(query, adhocFilters);
  182. // handle document query
  183. if (target.bucketAggs.length === 0) {
  184. metric = target.metrics[0];
  185. if (!metric || metric.type !== 'raw_document') {
  186. throw { message: 'Invalid query' };
  187. }
  188. const size = (metric.settings && metric.settings.size) || 500;
  189. return this.documentQuery(query, size);
  190. }
  191. nestedAggs = query;
  192. for (i = 0; i < target.bucketAggs.length; i++) {
  193. const aggDef = target.bucketAggs[i];
  194. const esAgg: any = {};
  195. switch (aggDef.type) {
  196. case 'date_histogram': {
  197. esAgg['date_histogram'] = this.getDateHistogramAgg(aggDef);
  198. break;
  199. }
  200. case 'histogram': {
  201. esAgg['histogram'] = this.getHistogramAgg(aggDef);
  202. break;
  203. }
  204. case 'filters': {
  205. esAgg['filters'] = { filters: this.getFiltersAgg(aggDef) };
  206. break;
  207. }
  208. case 'terms': {
  209. this.buildTermsAgg(aggDef, esAgg, target);
  210. break;
  211. }
  212. case 'geohash_grid': {
  213. esAgg['geohash_grid'] = {
  214. field: aggDef.field,
  215. precision: aggDef.settings.precision,
  216. };
  217. break;
  218. }
  219. }
  220. nestedAggs.aggs = nestedAggs.aggs || {};
  221. nestedAggs.aggs[aggDef.id] = esAgg;
  222. nestedAggs = esAgg;
  223. }
  224. nestedAggs.aggs = {};
  225. for (i = 0; i < target.metrics.length; i++) {
  226. metric = target.metrics[i];
  227. if (metric.type === 'count') {
  228. continue;
  229. }
  230. const aggField: any = {};
  231. let metricAgg: any = null;
  232. if (queryDef.isPipelineAgg(metric.type)) {
  233. if (queryDef.isPipelineAggWithMultipleBucketPaths(metric.type)) {
  234. if (metric.pipelineVariables) {
  235. metricAgg = {
  236. buckets_path: {},
  237. };
  238. for (j = 0; j < metric.pipelineVariables.length; j++) {
  239. pv = metric.pipelineVariables[j];
  240. if (pv.name && pv.pipelineAgg && /^\d*$/.test(pv.pipelineAgg)) {
  241. const appliedAgg = queryDef.findMetricById(target.metrics, pv.pipelineAgg);
  242. if (appliedAgg) {
  243. if (appliedAgg.type === 'count') {
  244. metricAgg.buckets_path[pv.name] = '_count';
  245. } else {
  246. metricAgg.buckets_path[pv.name] = pv.pipelineAgg;
  247. }
  248. }
  249. }
  250. }
  251. } else {
  252. continue;
  253. }
  254. } else {
  255. if (metric.pipelineAgg && /^\d*$/.test(metric.pipelineAgg)) {
  256. const appliedAgg = queryDef.findMetricById(target.metrics, metric.pipelineAgg);
  257. if (appliedAgg) {
  258. if (appliedAgg.type === 'count') {
  259. metricAgg = { buckets_path: '_count' };
  260. } else {
  261. metricAgg = { buckets_path: metric.pipelineAgg };
  262. }
  263. }
  264. } else {
  265. continue;
  266. }
  267. }
  268. } else {
  269. metricAgg = { field: metric.field };
  270. }
  271. for (const prop in metric.settings) {
  272. if (metric.settings.hasOwnProperty(prop) && metric.settings[prop] !== null) {
  273. metricAgg[prop] = metric.settings[prop];
  274. }
  275. }
  276. aggField[metric.type] = metricAgg;
  277. nestedAggs.aggs[metric.id] = aggField;
  278. }
  279. return query;
  280. }
  281. getTermsQuery(queryDef: any) {
  282. const query: any = {
  283. size: 0,
  284. query: {
  285. bool: {
  286. filter: [{ range: this.getRangeFilter() }],
  287. },
  288. },
  289. };
  290. if (queryDef.query) {
  291. query.query.bool.filter.push({
  292. query_string: {
  293. analyze_wildcard: true,
  294. query: queryDef.query,
  295. },
  296. });
  297. }
  298. let size = 500;
  299. if (queryDef.size) {
  300. size = queryDef.size;
  301. }
  302. query.aggs = {
  303. '1': {
  304. terms: {
  305. field: queryDef.field,
  306. size: size,
  307. order: {},
  308. },
  309. },
  310. };
  311. // Default behaviour is to order results by { _key: asc }
  312. // queryDef.order allows selection of asc/desc
  313. // queryDef.orderBy allows selection of doc_count ordering (defaults desc)
  314. const { orderBy = 'key', order = orderBy === 'doc_count' ? 'desc' : 'asc' } = queryDef;
  315. if (['asc', 'desc'].indexOf(order) < 0) {
  316. throw { message: `Invalid query sort order ${order}` };
  317. }
  318. switch (orderBy) {
  319. case 'key':
  320. case 'term':
  321. const keyname = this.esVersion >= 60 ? '_key' : '_term';
  322. query.aggs['1'].terms.order[keyname] = order;
  323. break;
  324. case 'doc_count':
  325. query.aggs['1'].terms.order['_count'] = order;
  326. break;
  327. default:
  328. throw { message: `Invalid query sort type ${orderBy}` };
  329. }
  330. return query;
  331. }
  332. getLogsQuery(target: any, querystring: string) {
  333. let query: any = {
  334. size: 0,
  335. query: {
  336. bool: {
  337. filter: [{ range: this.getRangeFilter() }],
  338. },
  339. },
  340. };
  341. if (target.query) {
  342. query.query.bool.filter.push({
  343. query_string: {
  344. analyze_wildcard: true,
  345. query: target.query,
  346. },
  347. });
  348. }
  349. query = this.documentQuery(query, 500);
  350. return {
  351. ...query,
  352. aggs: this.build(target, null, querystring).aggs,
  353. };
  354. }
  355. }